DeNexus Blog - Industrial Cyber Risk Quantification

OT Cyber Risk Intelligence Newsletter – August 2026 | DeNexus

Written by DeNexus | Aug 20, 2026, 4:56:31 AM

On July 30, a joint FBI/EPA advisory confirmed what operators across seven states had already lived through. In late July, water and wastewater utilities reported intrusions that followed a single documented method: remote access to internet-facing Rockwell MicroLogix PLCs, then IP and password changes that locked operators out. The reported effects included pressure loss, flooding, and boil-water notices. No drinking-water contamination was found anywhere. Attribution is still unsettled, with investigators calling Iranian involvement probable.

Strip away the attribution question and a more useful fact remains. The FBI named four factors that decided how far each incident went, and one of them was simply whether the utility could still run its process by hand. That's an engineering property: specifiable, testable, and evidenced. It's also exactly the kind of thing a loss estimate tends to skip.

This month's issue works through why that gap matters, and it starts with a plain test. A risk number is only useful when three people can trace it: a CFO who has to defend it to a board, an underwriter who has to price it, and an operator who can follow the logic back to their own architecture. If any of the three can't get from the evidence to the estimate, the number isn't ready. It's a calculation that won't survive the first serious challenge.

Download the August Newsletter →

The gap shows up most sharply in restoration, because restoration is where loss actually accumulates and it's the part most models guess at. When LockerGoga ransomware hit Norsk Hydro in 2019, the company put the cost at roughly $70 million. Most of that wasn't destroyed equipment. It was weeks of aluminum production running in degraded manual mode while systems were rebuilt. A model that estimates direct damage precisely but bounds restoration duration with an assumption nobody can locate has quantified the small number and guessed at the large one. Any reviewer who checks the work will find the guess.

So the discipline for the month is converting opaque quantification into traceable quantification. Opaque means benchmark averages, black-box scoring, or correlation assumptions nobody can point to. Traceable means three concrete things: facility-level inputs that can be audited, scenarios versioned with explicit feasibility conditions, and assumptions that carry a date and a methodology reference. Build those and the number can be challenged, updated, and defended. Skip them and it falls apart at the moment it's needed most.

That through-line connects the rest of the issue too. The water-sector method that CISA's updated PLC advisory now addresses. The Coca-Cola fairlife ransomware event that halted US production without touching Canadian lines. Marsh reporting a twelfth straight quarter of softening cyber rates, down 4% in Q2, with the caveat that outcomes still vary by risk quality. Each one comes back to the same question: can you trace the exposure to something specific, or are you only asserting it?

Inside DeNexus, that's the work the DeRISK Platform is built to do: quantify OT exposure in financial terms, then show which controls move the loss curve. But the principle stands on its own, whichever tools you use. A number you can't reproduce is a number you can't defend. And a number that can't be defended won't earn the terms it should, at exactly the moment it matters most.